VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2025-64135MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.

  • CVE-2025-47888MedMay 14, 2025
    risk 0.38cvss 5.9epss 0.00

    Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.

  • CVE-2023-40343MedAug 16, 2023
    risk 0.38cvss 5.9epss 0.01

    Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

  • CVE-2020-2230MedAug 12, 2020
    risk 0.38cvss 5.4epss 0.83

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

  • CVE-2019-10317MedApr 30, 2019
    risk 0.38cvss 5.9epss 0.01

    Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-10314MedApr 30, 2019
    risk 0.38cvss 5.9epss 0.01

    Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2018-1000173MedMay 8, 2018
    risk 0.38cvss 5.9epss 0.02

    A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

  • CVE-2017-1000402MedJan 26, 2018
    risk 0.38cvss 5.9epss 0.00

    Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.

  • CVE-2017-1000397MedJan 26, 2018
    risk 0.38cvss 5.9epss 0.00

    Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on…

  • CVE-2023-50770MedDec 13, 2023
    risk 0.37cvss 6.7epss 0.00

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that…

  • CVE-2022-34212MedJun 23, 2022
    risk 0.37cvss 5.7epss 0.01

    A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.

  • CVE-2017-2648MedJul 27, 2018
    risk 0.37cvss 6.8epss 0.01

    It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

  • CVE-2026-48927MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.

  • CVE-2025-31728MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-31727MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-31726MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-31725MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2023-24454MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2023-24442MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins…

  • CVE-2023-24440MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2023-24439MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-45386MedNov 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21612MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2314MedNov 4, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2274MedSep 16, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2154MedMar 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.

  • CVE-2020-2145MedMar 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.

  • CVE-2019-16572MedDec 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-16543MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10430MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10426MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10424MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10423MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10420MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10419MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10352MedJul 17, 2019
    risk 0.36cvss 6.5epss 0.10

    A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting…

  • CVE-2018-1000997MedJan 23, 2019
    risk 0.36cvss 6.5epss 0.03

    A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java,…

  • CVE-2018-1000406MedJan 9, 2019
    risk 0.36cvss 6.5epss 0.04

    A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory,…

  • CVE-2018-6356MedFeb 20, 2018
    risk 0.36cvss 6.5epss 0.04

    Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not…

  • CVE-2017-1000113MedOct 5, 2017
    risk 0.36cvss 5.5epss 0.00

    The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system access, or users with Extended Read access to the jobs it is used in, to retrieve those passwords. The Deploy to container Plugin…

  • CVE-2026-92133MedSep 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with…

  • CVE-2026-92132MedSep 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the…

  • CVE-2026-84677MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin…

  • CVE-2026-84674MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-84666MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording…

  • CVE-2026-84664MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.

  • CVE-2026-84663MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.

  • CVE-2026-84661MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel…

  • CVE-2026-84660MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.

  • CVE-2026-84654MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration…

Page 17 of 39